Evidence snapshot reviewed Sep 10, 2026GitHub checked Aug 21, 2026
Evidence-verifiedPlugin BundleModels & RoutingWeb Profile

dsh-autotier

Automatically routes DeepSeek Harness turns to strong, cheap, or vision model tiers.

At a glance

What it does

Automatically routes DeepSeek Harness turns to strong, cheap, or vision model tiers.

Use cases
Models & RoutingModel RoutingAutomationSecurity
Works with
Deepseek HarnessCordis
Compatibility

Web Profile
DeepSeek Harness 0.1.2-rc.1 or 0.1.5-rc.1; Node ^22.19.0 or >=24.0.0

Trust & status

Evidence-verified
Checked Sep 10, 2026, 2:23 PM UTC

Code-evidenced contributions

What it adds to DSH

Model ToolsAutomatic tier router

Routes requests between configured strong, cheap, and vision model tiers, with session-level /tier controls.

Mechanism evidence
Web UITier settings and composer control

Adds plugin settings and a composer tier control for viewing or changing session routing mode.

Mechanism evidence

Before you choose it

dsh-autotier is a DeepSeek Harness plugin bundle that classifies each turn and selects a configured model tier. It can use a strong tier for planning or review, a cheap tier for simpler work, and a vision tier for image-carrying requests. It also supplies /tier session overrides, routing-status tools, failure escalation, and a guard intended to deny configured high-risk activity while the cheap tier is active.

Best for

DeepSeek Harness users who want fewer manual model switches while retaining configurable routing behavior.

Common tasks

  • Route complex planning, debugging, and review work toward a stronger configured model tier.
  • Use a lower-cost tier for routine questions, retrieval, batch work, and daily tasks.
  • Inspect or override routing for one session with /tier, tier_status, or tier_route.
  • Configure tier providers, models, fallbacks, intent rules, guard settings, and escalation timing in the plugin settings.

Permissions and data

The manifest declares outbound-network and session-append permissions.

Permissions
  • network:outbound
  • session:append
Data handling
  • The supplied documentation says routing settings are stored through the shared autotier settings namespace.
  • The supplied documentation says it does not read or write ordinary files and does not read, log, or store credentials.
External services
  • Configured LLM provider, including a low-confidence judge request when enabled.
Credentials
  • No plugin-specific credential requirement is declared; configured model providers may have their own requirements.

Limitations

  • The supplied evidence does not establish that installation or runtime behavior was executed for this snapshot.
  • Intent rules are finite; unfamiliar complex phrasing can initially use the cheap tier before escalation or guard denial.
  • Escalation and learned state are in memory and reset after a Harness restart.
  • The guard is described as defense in depth, not a sandbox, and by default protects only the cheap tier.
  • A GUI model selection is not automatically treated as delegated routing; use routingMode: delegated or /tier off when needed.

What DSHub checked

  • The pinned source defines a DSH bundle patch, web client injection, and declared compatibility entries for DeepSeek Harness 0.1.2-rc.1 and 0.1.5-rc.1.
  • The immutable bundle structure and patch validation passed.
  • The manifest declares Apache-2.0 licensing, Node ^22.19.0 or >=24.0.0, outbound-network permission, and session-append permission.

What DSHub did not check

  • No installation, restart, model request, guard denial, escalation, or UI behavior was executed during this curation.
  • Registry package contents were not audited in the supplied evidence.

Pinned install

Install dsh-autotier

This plugin bundle does not have a DSH Plugin install action. Use its source documentation for the delivery method.

Visit the source project

Maintainer source

Project README

View at commit d96e660
Maintainer-authored contentCaptured from README.md on Sep 10, 2026. The text and repository-relative media are fixed to commit d96e6608408b with content hash e6a75f289131; provider-hosted badges may update independently. README commands are upstream documentation; the DSHub copy action above is the verified, version-pinned install.

dsh-autotier

Gitee License DSH plugin dsh-doctor Node CI Version

Automatic model-tier routing for DeepSeek Harness: one user instruction enters, one tier decision comes out — no manual model switching.

Complex intent (architecture, planning, debugging, multi-step engineering) is planned on the strong tier and then implemented on the cheap tier. Simple intent (questions, retrieval, batch chores, daily work) is designed and implemented on the cheap tier directly. While the cheap tier executes, high-risk tool calls are denied by a deterministic guard, and repeated failures escalate to the strong tier with a TTL fallback.

Compatibility

Harness Status
@deepseek-ai/dsh 0.1.2-rc.1 compatible; the compat workflow installs this line end-to-end
@deepseek-ai/dsh 0.1.5-rc.1 compatible; verified end-to-end (real profile install, --dump-config row, keyless headless smoke) and in the compat matrix
@deepseek-ai/cordis ^4.0.2, @deepseek-ai/schemastery ^3.18.2 peer baseline

Peer ranges name both published lines explicitly (`>=0.1.2-rc.1 <0.2.0 ||

=0.1.5-alpha.1 <0.2.0`), because a semver range whose only prerelease comparator sits on an earlier version tuple does not admit a later alpha. They are refreshed per published wave.

The plugin is host-plane only. It needs no agent preset of its own: the host row applies to every session. A one-line prompt section in your preset is optional and only makes the router's decisions visible to the model (see Install & uninstall).

What you get

  • Intent gate — every turn is classified from deterministic signals (message text, tool names, image presence, conversation length). The zero-token rule layer decides when it is confident; only a low-confidence turn calls the cheap judge model, and never on a cooldown.
  • Tier landing on the official seam — the decision is applied on the agent/request waterfall by returning a replacement provider/model/effort triple. Sampling scalars the session already chose (temperature, maxTokens, stop) are preserved.
  • Plan-mode handoff — a complex instruction enters plan mode on the strong tier; leaving plan mode drops back to the cheap tier for implementation.
  • High-risk guard — while the cheap tier executes, destructive commands (rm -rf, sudo, mkfs, git push --force, credential-file writes, …) are denied with a corrective message telling the model to escalate instead.
  • Failure escalation — repeated failures (optionally same-signature) raise the tier for a TTL; a model/route failure walks the configured fallback chain.
  • Manual escape hatches/tier auto|strong|cheap|off and the tier_status / tier_route tools. Setting routingMode: delegated (or /tier off) stops routing for a session that must keep its own model.
  • ctx.autotier service — a small read surface (status) plus the autotier/route veto waterfall and autotier/tier-changed event, so other plugins can observe or override a decision.

Quick start

npm i -g dsh1024
dsh1024 plugin --profile web add dsh-autotier

Then start (or restart) the harness. The row is appended to your profile's cordis.patch.yml; routing starts on the next turn with no further setup.

Install & uninstall

npm channel

npm i -g dsh1024
dsh1024 plugin --profile web add dsh-autotier

git channel

git clone https://github.com/PerryLink/dsh-autotier.git
cd dsh-autotier && pnpm install && pnpm run build
dsh plugin --profile web add .

Optional preset prompt section. The router works without it. To let the model know which tier it is running on, add one row to your agent preset (docs/preset-row.md has the exact block):

- insert:
    - id: autotier-prompt
      name: '@deepseek-ai/dsh-system-prompt'
      # sections: [...]  — see docs/preset-row.md

Uninstall

dsh plugin --profile web remove dsh-autotier

The row, its settings namespace, its command, its tools and its listeners are all removed with the plugin; nothing is written outside the settings document.

Configuration

Every key is validated at load time; an invalid value fails loudly instead of silently disabling routing. cordis.patch.yml in this repository documents the same keys inline.

Key Default Meaning
tiers.strong.provider deepseek-official Provider for the planning/review tier.
tiers.strong.model deepseek-v4-pro Catalog id of the strong model.
tiers.strong.effort high Adapter vocabulary off | low | high | max.
tiers.strong.followSession false false = this tier's effort overrides the session's.
tiers.strong.fallback [] Ordered provider/model landings when the tier is unavailable.
tiers.cheap.provider deepseek-official Provider for the implementation tier.
tiers.cheap.model deepseek-v4-flash Catalog id of the cheap model.
tiers.cheap.effort low Adapter vocabulary off | low | high | max.
tiers.cheap.followSession true true = inherit the session's effort so an explicit choice wins.
tiers.cheap.fallback [] Ordered provider/model landings when the tier is unavailable.
tiers.vision.provider deepseek-official Provider for image-carrying turns.
tiers.vision.model deepseek-v4-flash-vision-exp The catalog's image-capable model.
intent.ruleThreshold 0.7 Confidence at or above which the rule layer decides alone.
intent.attemptBand.enabled false Start the middle band on the cheap tier and escalate on a signal.
intent.attemptBand.tauLow 0.45 Lower bound of the attempt-first band.
intent.hysteresis.toStrong 0.8 Score that switches a cheap turn to strong.
intent.hysteresis.toCheap 0.6 Score below which a strong turn returns to cheap.
intent.rules [] Declarative rule table (when.patterns / when.tools / when.cwd, tier, priority).
intent.judge.enabled true Allow the low-confidence judge.
intent.judge.model '' Judge model id; empty = first catalog model containing flash.
intent.judge.temperature 0 Judge sampling temperature.
intent.judge.maxTokens 16 Judge output cap (it answers with one word).
intent.judge.cooldownMs 30000 Minimum gap between two judge calls.
intent.judge.timeoutMs 2000 Judge call timeout.
intent.judge.unavailableSkip 2 Consecutive judge failures after which the turn skips it.
intent.scenarios all true Per-scenario switches: coding, review, planning, retrieval, batch, daily, longText, multimodal.
intent.costMode balanced Ambiguity arbitration: cost-first | quality-first | balanced.
guard.enabled true Enable the deterministic high-risk guard.
guard.tiers [cheap] Tiers the guard protects.
guard.whitelist [] Commands, tools or path prefixes that never trip the guard.
guard.protectedPaths ['.dsh','AGENTS.md','package.json','.github/workflows'] Self-modification surfaces that force strong-tier review.
guard.interopDefend auto Relationship with dsh-defend: auto audits coexistence, none stays silent.
escalation.threshold 2 Failures within the window that raise the tier.
escalation.windowMs 60000 Failure-counting window.
escalation.ttlMs 180000 How long an escalation stays in effect.
escalation.fallbackTtlMs 300000 TTL used after a fallback landing was taken.
escalation.signature true Count same-signature recurrences instead of every failure.
routingMode auto auto | strong | cheap | delegated | off.

All keys can also be edited live from the autotier settings namespace ($DSH_HOME/settings.yaml); a write that violates a cross-field requirement is refused at save time and the last good policy stays in effect.

Tools & surfaces

Surface Kind Purpose
/tier command auto | strong | cheap | off | status; session-scoped override.
tier_status tool Current tier, mode, escalation TTL and guard state.
tier_route tool Route one intent string without sending a request (dry run).
ctx.autotier service status() read surface for other plugins.
autotier/route serial event Third parties may veto a proposed tier.
autotier/tier-changed emit event Observability when the effective tier changes.

Permissions & data

  • Files — the plugin reads nothing and writes nothing except through the shared settings service (the autotier namespace).
  • Network — the only outbound traffic is the judge call, which goes through the normal ctx.llm path and the configured provider.
  • Session log — the plugin appends no custom session events. The routing trail is the plugin logger plus the live autotier/tier-changed bus event; the only append it makes is the plan/mode fallback when the plan-mode service is absent. Custom event types are fail-closed on 0.1.2-alpha.1 and later, so no durable plugin-owned record is written.
  • Secrets — no credential is read, logged or stored by this plugin.

Security boundaries

  • The guard is a defence in depth, not a sandbox. It denies the patterns it knows on the cheap tier and never weakens dsh-defend, the approval service, or the sandbox policy. Keep those enabled.
  • The guard protects only the tiers listed in guard.tiers (cheap by default). A strong-tier turn is not blocked by design: the strong model is the reviewer.
  • If the guard itself throws, the call is escalated to the strong tier rather than allowed — a broken guard must not become an open door.
  • /tier off disables routing entirely; the harness then behaves exactly as it did before the plugin was installed.

Known limitations

  • The rule layer is deterministic and therefore finite: a novel phrasing of a complex request may start on the cheap tier and escalate only after a failure or a guard denial. The judge call covers the low-confidence middle.
  • Escalation is per-agent and in-memory; a harness restart starts from auto.
  • Tier switching resets the provider prompt cache for the changed request, so very chatty sessions may see a small cache-miss cost on the switch turn. The hysteresis thresholds exist to keep that rare.
  • The plugin routes conversation requests. Compaction and title generation are separate host seams; align their own model settings with the cheap tier if you want the same cost profile (docs/supporting-lanes.md).
  • followSession: true on the cheap tier means an explicit session model choice wins; in that case the cheap tier cannot force its own model.
  • The Settings card and composer tier pill shipped in 0.2.0. The card (routing mode, live tier landings, model catalog) lives in the Plugins settings section and the pill cycles the session mode from the composer.
  • A model picked in the GUI is not detected automatically. The router does not watch the agent-default-model document, so switching models there does not by itself stop routing — use routingMode: delegated or /tier off.
  • Fingerprint posteriors are in-memory. They reset on restart and re-learn from the judge's cold-start fallback; persisting them through the settings document is planned for v0.2.
  • The attempt-first middle band ships disabled. intent.attemptBand.enabled stays false until the calibration corpus and its metric gate land (v0.2).

Development

pnpm install
pnpm run typecheck      # against the local harness checkout type faces
pnpm run typecheck:ci   # against the published 0.1.5-rc.1 faces (what CI runs)
pnpm test
pnpm run build
pnpm run verify:self-contained
pnpm run verify:artifacts
pnpm pack

pnpm run build emits lib/types (tsc declarations) and lib/index.js (tsdown bundle). Tests use the published host packages directly — real Context, real session/tools/commands/settings services — plus one real Loader composition over a temporary cordis.yml.

Topics

dsh, dsh-plugin, deepseek-harness, deepseek, cordis, router, model-tier, cost, auto.

Contributors

PerryLink. Issues and pull requests are welcome at https://github.com/PerryLink/dsh-autotier/issues.

License

Apache-2.0. See LICENSE and THIRD_PARTY_NOTICES.md.

Operate deliberately

Install and manage

Prerequisites and target Profile

Target Web Profile

Delivery Dsh Bundle Git — PerryLink/dsh-autotier#d96e6608408bfb6fba39892f461521819a88a775

Verify, update, and remove

Show lifecycle commands
Verify
dsh plugin --profile web list

Compatibility and access

Compatible with declared DeepSeek Harness releases 0.1.2 Rc.1 and 0.1.5 Rc.1 DeepSeek Harness 0.1.2-rc.1 or 0.1.5-rc.1; Node ^22.19.0 or >=24.0.0

Review compatibility evidence

Risk facts

Network

May make outbound model-judge requests through the configured LLM provider.

Evidence
Session

Declares session append permission and can use a plan-mode fallback when that service is absent.

Evidence
Evidence and editorial reviewManifest, Bundle patch, distribution and freshness

Immutable evidence

Review status and source activity

AI reviewed

Use the pinned Git bundle source to inspect the declared defaults and customize provider/model settings before installation.

AI reviewed Sep 10, 2026, 2:24 PM UTCGitHub facts last checked Sep 10, 2026, 2:24 PM UTC

No material source change has been recorded since this evidence baseline.

Next step

Follow the Plugin installation workflow

Subscribe to material changes for dsh-autotier